Currently supported versions of the Exam Countdown Extension:
| Version | Supported |
|---|---|
| Latest | ✅ |
| < 1.0 | ❌ |
We recommend always using the latest version of the extension for the best security and features.
We take the security of the Exam Countdown Extension seriously. If you discover a security vulnerability, please follow these steps:
- Do NOT open a public GitHub issue for security vulnerabilities
- Send an email to [support@novatra.in] with:
- A description of the vulnerability
- Steps to reproduce the issue
- Potential impact assessment
- Any suggested fixes (if available)
Please provide as much information as possible:
- Type of vulnerability (e.g., XSS, data exposure, permission escalation)
- Affected version(s)
- Steps to reproduce
- Proof of concept (if applicable)
- Your contact information for follow-up
- Initial Response: Within 48 hours of report
- Status Update: Within 7 days with assessment
- Fix Timeline: Depends on severity
- Critical: 1-7 days
- High: 7-14 days
- Medium: 14-30 days
- Low: 30-90 days
When using this extension:
- Download from Official Sources: Only install from Chrome Web Store, Mozilla AMO or official repository releases
- Keep Updated: Enable automatic updates or regularly check for new versions
- Review Permissions: Check what permissions the extension requests
- Report Suspicious Behavior: Contact us if you notice unusual activity
- Backup Your Data: Export your exam data regularly
- We follow responsible disclosure practices
- Security researchers will be credited (with permission) after fixes are released
- We aim to fix vulnerabilities before public disclosure
- Security advisories will be published for significant issues
Security issues we accept:
- ✅ Cross-Site Scripting (XSS)
- ✅ Data leakage or unauthorized access
- ✅ Privilege escalation
- ✅ Security misconfigurations
- ✅ Injection vulnerabilities
Out of scope:
- ❌ Browser-level vulnerabilities
- ❌ Social engineering attacks
- ❌ Issues in third-party dependencies (report to them directly)
- ❌ Denial of service attacks
Security patches will be released as:
- Patch version updates (e.g., 1.0.x) for minor fixes
- Minor version updates (e.g., 1.x.0) for moderate issues
- Major version updates (e.g., x.0.0) for significant changes
For security concerns, please contact:
- Website: [https://novatra.in/]
- Security Advisory: Check GitHub Security Advisories tab
Thank you for helping keep the Exam Countdown Extension secure!